CVE-2026-73752

Summary

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)AOS-CX10.18.0000 <= 10.18.0001affected
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000 <= 10.17.1021affected
Hewlett Packard Enterprise (HPE)AOS-CX10.16.0000 <= 10.16.1051affected
Hewlett Packard Enterprise (HPE)AOS-CX10.13.0000 <= 10.13.1180affected
Hewlett Packard Enterprise (HPE)AOS-CX10.10.0000 <= 10.10.1180affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References